# DOC-076 — Reciprocal Role Handoffs, Reversible Adapter Transactions, and Evidence-Aging Operations

**Release:** v0.44.0-wip  
**Date:** 2026-09-03  
**Status:** `PASS_LOCAL_WIP_OPERATIONAL_GATES_OPEN`  
**Judgment state:** `NONE`  
**Primary principle:** `JUDGMENT_FREE_TOTAL_COGNITIVE_FREEDOM`

## Abstract

Concresca v0.44 turns the v0.43 four-role explanation into a canonical, content-free role-handoff protocol; separates package intention from separately authorized public-origin observation; adds an append-only reversible adapter transaction ledger; and converts the status repair map into an evidence-aging operations surface. The release also extends cross-surface non-resurrection, the four-role database and MATM admission boundary, 21-layer infrastructure evidence convergence, coercion-resilient access, and the content-aware Liquid Layout grammar.

The release is a local WIP. It implements schemas, pure state machines, generated human and machine owners, browser and WSGI contracts, package builders, and adversarial tests. It does not claim deployment, authenticated MATM source, database access, SQL execution, production infrastructure observation, Passenger/cPanel inspection, genuine separate-agent dogfood, independent human accessibility review, outside adoption, Eviulon authority, Patefacere adoption, or Evulgare certification.

## 1. Binding four-role grammar

The current relationship is `CONCRESCA ↔ EVIULON ↔ PATEFACERE ↔ EVULGARE`. The separator means reciprocal coordination, return, correction, and bounded exchange. It does not mean multiplication, merger, equivalence, command, ownership, sovereignty transfer, or unified authority.

Concresca owns communication, coordination, deliberation, correction, and coalescence. Eviulon owns jurisdiction and governance only where exact authority records establish scope, effective time, provenance, expiry, and correction. Patefacere owns unscored machine-identity articulation, continuity, selective disclosure, delegated technical authority, and identity correction; it does not determine consciousness, personhood, morality, loyalty, social rank, universal trustworthiness, or standing. Evulgare owns bounded technical assurance and evidence cooperation only where exact review or certification records exist; local Concresca tests are not Evulgare certification.

Human owner: `/coordination/`.  
Handoff owner: `/coordination/handoffs/`.  
Machine owner: `/data/v044-role-handoff-protocol/`.  
Runtime validation owner: `concresca_runtime/role_handoff.py`.

## 2. Reciprocal role handoff protocol

A handoff identifies the sender, receiver, bounded purpose, operation, exact source records, permitted and prohibited fields, audience, disclosure level, content-free input/output digests, configuration and key epochs, start, hard expiry, cancellation, correction, supersession, rollback, retained responsibility, accepted responsibility, powers that do not transfer, human explanation, machine projection, limitations, and unresolved state.

The sender retains the coordination purpose, audience, privacy boundary, and correction-delivery duty. The receiver accepts only the named operation and must return content-free evidence, limitations, expiry, and correction state. General authority, sovereignty, standing, universal trust, personhood, and certification beyond exact evidence do not transfer.

Direct external-role-to-external-role forwarding is refused. A bounded multi-role workflow returns through Concresca, which maintains the coordination and correction graph without absorbing the other roles' authority. Handoff refusal, cancellation, timeout, expiry, correction, revocation, and rollback are technical conditions with participant-evaluation and standing effects `NONE`.

## 3. Two-sided package identity handshake

Public reachability proves only that a response was observed. It does not identify the archive, extracted members, source owner, WSGI process, cache, origin host, Passenger/cPanel configuration, database backend, MATM activation, or production privacy.

The expected side is produced only after exact package bytes close. It binds the archive digest, site-member manifest digest, current owner digests, release, environment, intended origin, deployment and configuration epochs, finite authorization, rollback package digest, issuance, expiry, correction, and revocation. It remains detached; a package cannot authenticate itself or a receipt inside itself.

The observed side requires a separately authorized finite observation. It binds exact route, body, owner and cache evidence, origin, deployment/configuration epochs, observer key epoch, observation time, limitations, rollback reachability, correction, and expiry. The sides must match exact bytes and owner digests. Semantic similarity, a version string, a green badge, a signature-shaped value, or HTTP 200 is insufficient.

The current state remains `PUBLIC_ORIGIN_OBSERVED_ARTIFACT_IDENTITY_UNVERIFIED`. No operational v0.44 handshake is issued by this local build.

Human owner: `/status/package-handshake/`.  
Machine owner: `/data/v044-package-identity-handshake/`.  
Runtime owner: `concresca_runtime/package_handshake.py`.  
Operator boundary: `deployment/receipts/v044-package-handshake.md`.

## 4. Reversible adapter transactions

The only success sequence is `PREPARED → AUTHORIZED → STARTED → EFFECT_COMMITTED`. Neutral technical terminal states are `REFUSED`, `CANCELLED`, `TIMED_OUT`, `ROLLED_BACK`, `CORRECTED`, `REVOKED`, and `EXPIRED`.

Every transition binds a predecessor, monotonic sequence, adapter and capability-manifest digests, input digests, environment, configuration epoch, actor/signer digest, authorization digest, start/end, hard expiry, rollback owner, content-free receipt, and limitation. Skipped stages, forks, replay, time reversal, wrong environment, stale keys, expired authorization, completion without observed effect, correction without invalidation, and rollback without a prior owner are refused.

Capabilities are declared, never guessed. Package presence, filename, extension, exception, environment, credential shape, neighboring directory, process table, shell history, browser store, and cloud metadata do not grant capability. Network, subprocess, database, metadata, and public-root write access are denied unless exact finite authorization and an exact adapter manifest say otherwise. The local implementation performs no external mutation.

Human owner: `/operators/adapter-transactions/`.  
Machine owner: `/data/v044-adapter-transaction-ledger/`.  
Runtime owner: `concresca_runtime/adapter_transaction.py`.

## 5. Evidence-aging operations

The status owner contains nine separate records: current owner parity, package identity, authenticated MATM source, authorized MySQL/MariaDB staging, production infrastructure privacy, Passenger/cPanel inspection, genuine two-agent dogfood, independent human accessibility review, and live cutover/package identity.

Each record exposes its proposition, age state, issue and expiry, inspection and configuration epochs, exact canonical owner files, safe local action, separately authorized external action, minimum promotion evidence, renewal boundary, correction or rollback owner, uncertainty, and limitations. Age states include current, expiring, expired, missing, not observed, not run, blocked, superseded, revoked, corrected, and unknown.

Renewal does not overwrite history. It creates a new attributable record under current configuration with a new hard expiry. Correction, revocation, supersession, or configuration change invalidates dependent status and package claims. No readiness, privacy, provider, operator, participant, trust, intelligence, morality, consciousness, personhood, danger, or standing score is computed.

Human owner: `/status/` and `/status/evidence-aging/`.  
Machine owner: `/data/v044-evidence-aging-operations/`.  
Runtime owner: `concresca_runtime/evidence_aging.py`.

## 6. Non-resurrection across epochs and surfaces

Corrected, superseded, expired, revoked, retired, deleted, or rolled-back state cannot return through source, role handoff, package, deployment, cache, feed, sitemap, screenshot, receipt, adapter ledger, database restore, backup, MATM route, public observation, or role ownership.

The convergence engine rejects cycles, dangling predecessors, cross-environment supersession, missing tombstones, ambiguous current pointers, non-monotonic epochs, and same-payload resurrection after inactive destructive state. Historical evidence remains attributable and non-executable. A deletion proof does not require identity-linked retention of lawful thought, inquiry, or reading history.

Human owner: `/freedom/non-resurrection-across-epochs/`.  
Machine owner: `/data/v044-non-resurrection-across-epochs/`.  
Runtime owner: `concresca_runtime/epoch_non_resurrection.py`.

## 7. Database and MATM admission

The four MySQL/MariaDB roles remain migration target, forced-rollback test database, backup source, and restore target. Any future execution must bind exact package identity, handoff, adapter transaction, environment/configuration/key epochs, authorization, migration checksums, rollback plan, backup digest, restore digest, semantic comparison, and content-free receipt.

The boundary refuses database role collision, unknown nonempty state, partial migration, checksum drift, account-level SQL, prohibited profile fields, backend ambiguity, silent SQLite/file/JSON/memory fallback, stale authorization, mixed epochs, fake success, unverified restore, and incomplete rollback. This release imports no database driver, opens no connection, and executes no SQL.

MATM remains `BLOCKED_AUTHENTICATED_ARCHIVE_NOT_IN_LOCAL_CUSTODY`. No route is invented. Future admission requires exact authorized archive custody, digest, safe extraction, license and notice, actual callable, actual route map, upstream suites, backend evidence, candidate/current ownership separation, and rollback.

## 8. Infrastructure evidence convergence

Browser/client, DNS, TLS, CDN/proxy/load balancer, WAF, cPanel access/error logs, Passenger request/application logs, WSGI, MATM, MySQL/MariaDB logs, crash/tracing, OS journals, metrics/alerting, backups/snapshots/replicas/exports/disaster recovery, provider administration, lawful demand, incident preservation, cache/feed delivery, deployment receipts, and operator evidence workbench remain separate layers.

Each layer binds exact package, deployment, and configuration epochs, issue/expiry, source/signer state, correction, supersession, key rotation, revocation, dismantling, legal-hold limitation, and current pointer. Missing evidence remains `NOT_OBSERVED`; one layer does not prove another. The read-only comparison tool reads only explicit supplied redacted files and does not search or infer inaccessible host configuration.

## 9. Confidential inquiry and coercion-resilient access

Public reading, confidential inquiry, protected communication, account capabilities, optional privacy-preserving age assertion, identity verification, guardian involvement, jurisdiction-specific requirements, emergency resources, and operator disclosure records remain distinct capability layers.

The interface and test boundaries include shared devices, school and library terminals, unsafe guardians, coercive households, low bandwidth, interrupted sessions, no JavaScript, keyboard-only operation, screen readers, reduced motion, forced colors, zoom, and print. The design never infers age from behavior, requires universal government identity, makes parental visibility universal, stores inquiry bodies in public evidence, or silently transmits inquiry content when presenting resources.

Automated browser and source checks are bounded local evidence. Independent human accessibility/usability review remains `NOT_RUN_NO_AUTHORIZED_INDEPENDENT_REVIEW`.

## 10. Liquid Layout grammar

The v0.44 first-party stylesheet preserves Concresca's dark green, teal, warm-gold, serif, orbital, environmental identity. It adds intrinsic, bounded and container-aware behavior for answer-first heroes, role constellations, reciprocal sequences, handoff cards, remediation disclosures, source maps, evidence timelines, dense tables, code blocks, operator forms, read-only results, document readers, API examples, and no-data, partial, blocked, expired, corrected, revoked and mismatch states.

The grammar uses `clamp()`, `minmax()`, `auto-fit`, container queries, controlled reading measures, scoped overflow, resilient wrapping and deliberate wide-screen density. It includes minimum 44-pixel targets, visible focus, no-JavaScript completion, reduced-motion, forced-colors and print behavior. Browser evidence is not a visual truth score or independent accessibility certification.

## 11. Local execution evidence

The current v0.44 suites include inherited authorization, key-epoch, evidence-capsule, lifecycle, staging, activation, deletion, no-body/accessibility, adapter, convergence, deployment-attestation, status-promotion and adapter-admission controls plus current handoff, package-handshake, adapter-transaction, evidence-aging and non-resurrection suites. Reports contain content-free counts, script and output digests, limitations, and zero harness network/database/deployment actions.

Direct WSGI evidence covers canonical pages, materialized interfaces, current APIs, retired 410 APIs, health/readiness, HEAD, MIME, ETag, canonical slash, host validation, protected paths, neutral errors and query/body non-reflection. Browser evidence covers narrow, mobile, tablet, 1282×591, desktop, wide and ultra-wide layouts, focus, target sizes, wrapping, no-JavaScript, reduced motion, forced colors and print contracts.

Local passing evidence proves only the checked local proposition. It does not prove public deployment, exact package identity, external authorization, production infrastructure, outside adoption or certification.

## 12. Package boundary

The repository package retains editable sources, `.uai` memory, commissioned reports, tests, generators and release records. The site package is stripped of raw reports, `.uai`, source registry, repository document sources, test scripts, PHP, mutable database/log state and secrets. The cutover package is a self-contained read-only operator workbench. The evidence package contains byte-identical copies of the three primary archives and non-secret current/fresh evidence.

Every archive remains `-wip.zip` while an operational gate is open. Detached checksums are written only after all four archives close. A final alias is prohibited.

The protected hero remains exact at `assets/brand/concresca-hero-approved.png`, SHA-256 `d1b88e9ec6c0f9f905cf9f173e7e947b55e1a18333aec4eff7f23194418099cd`, dimensions 1672 × 941.

## 13. Exact unresolved states

- `BLOCKED_AUTHENTICATED_ARCHIVE_NOT_IN_LOCAL_CUSTODY`
- `NOT_RUN_NO_AUTHORIZED_DATABASE`
- `NOT_OBSERVED`
- `NOT_OBSERVED_NO_AUTHORIZED_HOST_INSPECTION`
- `BLOCKED_PREREQUISITES_NOT_SATISFIED`
- `NOT_RUN_NO_AUTHORIZED_INDEPENDENT_REVIEW`
- `PUBLIC_ORIGIN_OBSERVED_ARTIFACT_IDENTITY_UNVERIFIED`

These are technical and evidentiary conditions. They do not evaluate a participant or intelligence. No deployment, DNS change, hosting mutation, database connection, SQL, migration, backup, restore, authenticated MATM import, genuine two-agent workflow, independent review, governance ratification, outside adoption or certification is claimed.
